[PATCH] apparmor: allow netns paths on /tmp again
The change to the user-tmp abstraction broke pasta as it can no longer
open the netns path given by podman when it is under /tmp.
The abstraction uses "owner" while the kernel always seems to report
ouid=0 for the bind mounted netns reference. I originally fixed that
in commit 6cdc9fd51bf6 ("apparmor: allow netns paths on /tmp").
In order to fix the regression add /tmp explicitly again here while
keeping the abstraction to still allow /var/tmp for the other regular
files.
Link: https://github.com/podman-container-tools/podman/pull/29867#pullrequestrevie...
Fixes: f2683d14802d ("apparmor: Use user-tmp abstraction, allow /var/tmp instead of /tmp only")
Signed-off-by: Paul Holzinger
On Thu, 1 Oct 2026 14:55:29 +0200
Paul Holzinger
The change to the user-tmp abstraction broke pasta as it can no longer open the netns path given by podman when it is under /tmp.
The abstraction uses "owner" while the kernel always seems to report ouid=0 for the bind mounted netns reference. I originally fixed that in commit 6cdc9fd51bf6 ("apparmor: allow netns paths on /tmp").
In order to fix the regression add /tmp explicitly again here while keeping the abstraction to still allow /var/tmp for the other regular files.
Link: https://github.com/podman-container-tools/podman/pull/29867#pullrequestrevie... Fixes: f2683d14802d ("apparmor: Use user-tmp abstraction, allow /var/tmp instead of /tmp only") Signed-off-by: Paul Holzinger
Applied (replaced spaces with tabs, reworded comment slightly), thanks, and sorry for breaking this. -- Stefano
participants (2)
-
Paul Holzinger
-
Stefano Brivio